Defense Evasion via WSL Enablement using DISM
Adversaries may attempt to enable the Windows Subsystem for Linux (WSL) using the legitimate DISM utility to facilitate the execution of Linux-based tools and bypass Windows-specific security controls.
The Windows Subsystem for Linux (WSL) allows users to run Linux distributions and command-line tools natively on Windows. Adversaries often abuse this feature to evade security protections, as Linux-based tooling and bash environments may not be monitored by security tools configured strictly for Windows binaries. This technique involves using the built-in Deployment Image Servicing and Management (DISM) utility to programmatically enable the WSL feature on a compromised host. By transitioning the environment to include Linux capabilities, attackers gain a platform to execute malicious scripts, deploy Linux-based malware, or perform post-exploitation tasks while minimizing their footprint on the Windows host's primary security stack. Monitoring for unauthorized use of DISM to modify Windows features is a critical component of endpoint security.
Attack Chain
- Attacker gains initial access to the Windows host through phishing or exploit.
- Attacker identifies that WSL is not enabled, limiting their ability to execute custom Linux payloads.
- Attacker executes
Dism.exewith administrative privileges. - Attacker supplies the
/Enable-Featureargument targetingMicrosoft-Windows-Subsystem-Linux. - The OS enables the subsystem, potentially requiring a system reboot or further configuration.
- Attacker downloads or executes Linux-native payloads or shells (e.g., bash).
- Attacker performs malicious activity, such as exfiltration or lateral movement, using the Linux environment.
Impact
Successful exploitation allows an attacker to operate within a Linux environment on a Windows host, effectively bypassing security controls that lack visibility into Linux-native execution or shell activity. This can lead to persistent access, enhanced capability to deploy complex cross-platform malware, and increased difficulty for incident responders to perform forensic analysis, as malicious activity may be logged in Linux-specific locations rather than standard Windows event logs.
Recommendation
Prioritize monitoring of the Dism.exe utility and establish a baseline for authorized feature changes in the environment.
- Deploy the provided Sigma rule to detect
Dism.exeinvocations that enable WSL. - Review administrative activity logs for
Dism.exeexecution across all endpoints. - Establish a process for identifying and authorizing WSL usage within the enterprise.
- Enable Sysmon process-creation logging (Event ID 1) to ensure the detection of process command-line arguments.
Immediate actions
Deploy Sigma detection rule to SIEM
Threat Hunt
Search historic logs for Dism.exe executing with WSL-related arguments
Data: Process creation logs
Mitigations
Restrict administrative rights for DISM to authorized personnel
T1202
Detection coverage 1
Detect Windows Subsystem for Linux Enabled via Dism Utility
mediumDetects attempts to enable the Windows Subsystem for Linux using Microsoft Dism utility. Adversaries may enable and use WSL for Linux to avoid detection.
Detection queries are available on the platform. Get full rules →